Searching for just a few words should be enough to get started. If you need to make more complex queries, use the tips below to guide you.
Article type: Research Article
Authors: Ourston, Dirk; * | Matzner, Sara | Stump, William | Hopkins, Bryan
Affiliations: Applied Research Laboratories, The University of Texas at Austin, P.O. Box 8029, Austin, TX 78713-8029, USA Tel.: 512-835-3899; Fax: 512-490-4254; E-mail: ourston@arlut.utexas.edu, matzner@arlut.utexas.edu, stump@arlut.utexas.edu, bhopkins@arlut.utexas.edu
Correspondence: [*] Corresponding author.
Abstract: This paper examines the issues involved with responding to complex Internet attacks. Such attacks characteristically occur in stages over extended periods of time and allow specific actions in a particular stage to be interchangeable. The stages can be extremely difficult to correlate because they are separated in time, and these effects can be deliberately obscured to achieve the goals of the attacker. We have chosen an approach to intrusion detection using Hidden Markov Models (HMMs) that explicitly addresses these issues. As part of our research we also developed a methodology for labeling examples that reduced the effort involved from that of labeling thousands of training examples to that of labeling less than two hundred feature values. When compared with two classic machine learning algorithms, decision trees and neural nets, the HMM algorithm provides an approximately five-% performance advantage over the decision tree algorithm, and at least a thirty % advantage over neural nets, at all training levels. The HMM performance advantage over decision trees is shown to increase as the complexity of the attack increases. The HMM performance advantage also increases as the number of training examples decreases. This last result indicates that the HMM algorithm may have additional benefit when examples of a particular attack type are rare.
DOI: 10.3233/JCS-2004-12201
Journal: Journal of Computer Security, vol. 12, no. 2, pp. 165-190, 2004
IOS Press, Inc.
6751 Tepper Drive
Clifton, VA 20124
USA
Tel: +1 703 830 6300
Fax: +1 703 830 2300
sales@iospress.com
For editorial issues, like the status of your submitted paper or proposals, write to editorial@iospress.nl
IOS Press
Nieuwe Hemweg 6B
1013 BG Amsterdam
The Netherlands
Tel: +31 20 688 3355
Fax: +31 20 687 0091
info@iospress.nl
For editorial issues, permissions, book requests, submissions and proceedings, contact the Amsterdam office info@iospress.nl
Inspirees International (China Office)
Ciyunsi Beili 207(CapitaLand), Bld 1, 7-901
100025, Beijing
China
Free service line: 400 661 8717
Fax: +86 10 8446 7947
china@iospress.cn
For editorial issues, like the status of your submitted paper or proposals, write to editorial@iospress.nl
如果您在出版方面需要帮助或有任何建, 件至: editorial@iospress.nl